CVE-2025-0134: Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM (Severity: LOW)
Published May 14, 2025
·Updated
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.
Affected Software
1 affected componentFixes available
Palo Alto Networks Cortex XDR Broker VM<26.0.119, =26.0.0
26.0.119
Remediation
Mitigation
There are no known workarounds or mitigations for this issue.
Information
This issue is fixed in Cortex XDR Broker VM 26.0.119, and all later Cortex XDR Broker VM versions.
* If you enabled automatic upgrades for Broker VM, then no action is required at this time.
* If you did not enable automatic upgrades, then we recommend you do so for Broker VM to ensure that you always have the latest security patches installed in your software.
Event History
May 14, 2025
Advisory Published
via Palo Alto Networks·04:00 PM
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0134?
The severity of CVE-2025-0134 is critical due to the potential for authenticated users to execute arbitrary code with root privileges.
2
How do I fix CVE-2025-0134?
To fix CVE-2025-0134, upgrade the Palo Alto Networks Cortex XDR Broker VM to version 26.0.120 or later.
3
Who is affected by CVE-2025-0134?
CVE-2025-0134 affects users of Palo Alto Networks Cortex XDR Broker VM versions 26.0.0 to 26.0.119.
4
What types of attacks does CVE-2025-0134 enable?
CVE-2025-0134 enables authenticated users to perform code injection attacks leading to arbitrary code execution on the host OS.
5
When was CVE-2025-0134 published?
CVE-2025-0134 was published in the 2025 vulnerability disclosure cycle.